SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-52691

HIGH · CVSS 8.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Apache Griffin Hive Metastore Module is vulnerable to SQL Injection due to improper neutralization of special elements in SQL commands. This flaw can lead to unauthorized data access and manipulation, posing significant risks to any systems still utilizing this retired software. Organizations relying on this module should prioritize immediate migration to supported alternatives or implement strict access controls to mitigate potential exploitation.

CVE
CVE-2026-52691
Severity
HIGH
CVSS
8.8
EPSS
0.28%
Apache

Original NVD Description

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module.  This issue affects Apache Griffin Hive Metastore Module: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.